InsideCRA
InsideCRA › Definitions › Severe incident

Defined term

Severe incident

The second reporting trigger, aimed at the product's own security.

LAW Defined in Article 3 (Art. 3(44)). The verbatim definition is in the official text of Article 3; only the Official Journal is authentic.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

A severe incident having an impact on the security of the product is the second Article 14 trigger F-030, running the same 24-hour and 72-hour notification rhythm as the vulnerability limb F-029. The phrase to underline is "of the product": this is about incidents that negatively affect, or are capable of negatively affecting, the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that have led or could lead to the introduction or execution of malicious code, not every operational outage a company suffers F-030.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Not sure whether this applies to your product? Check if the CRA applies to you on CRARequired.